Privacy Program Building
October 7, 2026

Why Privacy Leaders Now Own AI Governance

EPisode
4
Leader
Joyce Chen
Role
Founder
Current company
Chen & Foundry
Date
Oct 7, 2026

How do privacy and risk leaders stay defensible when laws, technology, and AI are all changing faster than ever?

‍

In this episode of Trust at Speed, TerraTrue founder and CEO Jad Boutros sits down with Joyce Chen, founder of Chen & Foundry, to explore what it takes to lead through ambiguity, how privacy can keep pace with engineering teams moving at AI speed, and why privacy leaders are increasingly taking on AI governance.

‍

Joyce has led privacy at Nova Credit, Pendo, and Foursquare. Earlier this year she founded Chen & Foundry, where she helps scaling startups build defensible privacy and AI governance programs.

‍

The conversation starts with what Joyce calls defensibility under ambiguity. With laws, precedent, and AI risk all shifting quickly, she argues that legal leaders can't just apply the letter of the law. They need to understand the political, policy, and economic context behind regulation, and keep up with new risk vectors as they emerge.

‍

From there, Joyce and Jad discuss embedding privacy into engineering. Joyce makes the case for "guardrails, not gates," and explains why the relationship has to be a two-way street. Privacy lawyers need to upskill in how the technology works, engineers need to understand what personal data is, and both sides need to check their priors, because the same words often mean very different things across disciplines. She also shares why she thinks assistive compliance agents that flag issues early are part of the future.

‍

Joyce explains why a chief privacy officer is really a data lawyer, and why AI is ultimately another data processing system. With the CFO, the board, and HR all invested in how AI gets adopted, she sees the partnership between the CPO and the CISO as essential to effective AI governance.

‍

For startups, Joyce cautions against burying fast-moving teams in audit paperwork. Instead, she points to AI observability, meeting teams at the point of agentic deployment, and getting to a "single pane of glass" view of how data flows through an organization. Her view is that gatekeeping and after-the-fact auditing won't hold up at the speed companies are moving now.

‍

Topics covered include:

  • Defensibility under ambiguity for privacy and risk leaders
  • Why legal leaders need to understand policy and political context
  • Guardrails, not gates: embedding privacy into engineering
  • Why privacy and engineering is a two-way street
  • Compliance agents and the changing role of the lawyer
  • How privacy teams can leverage AI instead of blocking it
  • Why chief privacy officers are really data lawyers
  • The CPO and CISO partnership in AI governance
  • Building AI governance programs at Series A to Series C startups
  • AI observability and coming in earlier
  • Why after-the-fact auditing can't keep pace with agentic development
Episode Transcript

Jad: Welcome to the show. I'm Jad Boutros, founder and CEO of TerraTrue. In this series, we sit down with top experts across privacy, security, and AI to unpack hard-earned lessons and explore how they're navigating an ever-changing landscape.

‍

Today we're joined by Joyce Chen. Joyce has led privacy teams across high-growth tech companies and enterprise giants alike, including Snap, Facebook, Foursquare, and Pendo. Earlier this year, Joyce founded Chen & Foundry, where she helps scaling startups build defensible privacy and AI governance programs. Joyce, thank you so much for joining us.

‍

Joyce: Absolutely. I'm delighted to be here.

‍

Jad: Fantastic. We love speaking with you. Joyce, I want to start with something you recently spoke about, which really resonated with me. You talked about a very important trait for privacy leaders and risk leaders: defensibility under ambiguity. I'd love to hear more about what you have in mind around ambiguity, and also what some potential defensibility mechanisms are.

‍

Joyce: Absolutely. I think it's no surprise to anyone that we're living in very fast-moving times, both in how laws are enacted, applied, and changed. There's a lot happening in administrative law, in what is precedent and what will change precedent very suddenly. And of course AI, data, and security. Jad, you know better than most people the threats that AI poses to cybersecurity. Everyone who works in trust and safety is grappling with how to respond to these issues and address them appropriately.

‍

As a privacy leader, or any trust, safety, compliance, or ethics leader, this is really a test of existing skills, but also of the ability to adapt them, and to actually move your organization safely through this turbulent and unsettling landscape of change.

‍

Generally, I see the role of any legal leader as not strictly applying the letter of the law, but also looking at the larger political changes. What are the policy implications? What is the context behind what actually comes down the pike when it comes to laws, regulations, and guidance?

‍

So moving forward, for any trust and safety, privacy, or security leader, understanding how laws and standards are matrixed into what is happening globally, and certainly within the country, and the larger context around that, is going to be all the more paramount.

‍

A lot of people are probably sick of hearing about AI and how it's changing the world. But it has, and it will continue to. There's a huge body of work around straightforward reasoning. It's not going away, but we now have a very powerful tool, AI, to do a lot of that for us. Being at the frontier of understanding how laws are passed, why they're passed, how the larger economy and macroeconomics fold into that, and what the new threats and risk vectors are to keep abreast of: those are all the things at the frontier. Leaders will have to socialize and network well, meet people like you, and continue to lead with purpose and integrity.

‍

Jad: That's a great perspective, Joyce. And rest assured, we're going to ask you more about your thoughts on AI and how it's changing things. But before we get there, I want to ask you about embedding privacy and compliance into engineering. As you know, engineering is moving faster than it ever has. As you think about ways to collaborate better with product and engineering, or embed yourself more into their workflows, what are some practical thoughts and recommendations you have? Essentially, how do you make sure the friction doesn't come at the end, and that they don't think of legal and privacy as a gate before they can launch?

‍

Joyce: I think the tenet of providing guardrails, not gates, is still very much true. If anything, it's more true, because the last thing you want as a trust and safety leader is to be the one who just blocks and says no. That doesn't build trust with your colleagues, and it doesn't show proper prioritization for the company.

‍

At the same time, it is very much your responsibility to ensure the organization can continue to innovate safely and meet its targets without any huge negative disruption. Especially as dev cycles are increasing because of AI, there are now coding agents that work while we sleep.

‍

There's a lot of complexity that security leaders especially, Jad, are grappling with. How do you maintain proper ID management? Instead of talking about things in the ether, how do you know what data belongs to which systems and applications, who has access, and how those access points are controlled, or at least documented and monitored? A lot of what has sometimes been talked about philosophically now has to actually be implemented and auditable, because of what AI has introduced: the freedom, the increase in innovation, and certainly the increased use of data, because that's just what AI does.

‍

So I really see it as a two-way street. It's just as incumbent on privacy teams and privacy lawyers at companies to upskill in how the tech works. You want to come in with at least some basic knowledge so you have some means of actually engaging with your engineering partners.

‍

On the other end, engineering partners need to be able to understand the universe of what privacy is involved with and what personal data is. That's a training aspect I continue to talk about time and again in all of my trainings.

‍

But it's also about checking your priors. When you come from two different disciplines, you're oftentimes using the same words to talk about completely different concepts. That miscommunication is very well-intentioned, but it's ultimately miscommunication, and it can lead to a lot of issues down the line. So being able to listen well, probe, be willing to take feedback, and apply it in ways you hadn't thought about before is going to be all the more important.

‍

Law and legal practice will continue, but they have to change over time. I've spoken to clients who've asked, can you build a compliance agent that will let us know when we're starting to get out of line? And I said, yeah, maybe. Maybe we can do that.

‍

Jad: It's the future, yeah.

‍

Joyce: I think that is the future. Something assistive isn't going to give you straight-up legal advice about your exact, discrete situation, but it can flag things for you and let you know, hey, now's a good time to talk to your partner and see whether this is following your internal privacy policy, or your external privacy policy.

‍

The role of the lawyer is changing, and the same goes for the role of the engineer. All roles across the board are changing. Being able to lean into that, roll up your sleeves, and test and iterate alongside your technical partners is going to be all the more critical moving forward.

‍

Jad: That's great insight. I also love thinking about it agentically, because, as you said, developers are increasingly leveraging AI capabilities to build faster and better, and to do that more autonomously. It's clear AI is changing the way every single team within a business does its work. You started alluding to how the role of privacy counsel is changing. Over the past six months or a year, have you seen any practical ways that privacy teams have embraced AI capabilities to scale better or be more effective at their work?

‍

Joyce: Ooh. When you're the one leading privacy, it's sometimes hard to have really good insight into how other companies handle privacy. But speaking for myself, I would love to see privacy be more prevalent. Those of us who choose to work in trust and safety fields do so because we believe in the import of what we do. We want to protect people and their data, and create the anticipated outcomes that businesses expect and that are good for society.

‍

Providing easier means to access privacy knowledge is something I'm very passionate about. Instead of seeing cutting-edge technology like AI as something to mitigate, block, or slow down, which for one isn't possible, and if you try to take that tack, I don't think it'll work well for you, leverage it. Let it augment what you do.

‍

That also means getting really good at it, or trying to be the best you can at it, so you can defensibly use and leverage AI to provide just-in-time guidance and really relevant counsel to your teams.

‍

Ultimately, I think people and organizations are generally all trying to do the right thing. I don't think anyone wakes up one day and says, I want to make sure we're not compliant. But systems can sometimes break. Nothing is perfect. And it's going to be the role of the head of privacy, security, compliance, ethics, or trust, however you name it in your organization, to provide that assurance, both within the company and to your external stakeholders, that you're conducting business the way you expect. I hope that answers your question.

‍

Jad: This is great. Let me follow up in a different way and get your perspective. There was a study from the IAPP indicating that 69% of the chief privacy officers they surveyed have taken on significant responsibility in AI governance. So, going back to your point about changing roles, privacy has been taking more and more direct responsibility for AI governance.

‍

And you're now advising startups, maybe Series A to Series C, on how to build an effective AI governance program. Tell us a little about what it looks like to build an effective AI governance program for companies at that stage. And how do you, to your point, make sure you're not the department of no, and that you're embracing the technology and working well with the business on its needs in that space?

‍

Joyce: Absolutely. The reality is that "chief privacy officer," or any privacy leader, who is oftentimes a lawyer, is sometimes a misnomer. You're not so much a privacy lawyer as a data lawyer. The regulations around data and security are one of the disciplines that regulate data, or should regulate data. You're basically applying all the laws and regulations relevant to the processing, the collection, and the movement of data across borders, within your own company, and between different stakeholders.

‍

What that essentially means with AI is that AI is like any other data processing system. Its raw material is data. That has always been the case, but now you're talking about the speed at which data is being processed, the potential new endpoints being created, and new combinations, new ways of matching, and unstructured processing of data sets. Understanding the universe of data you hold as a company has always been under the remit of your chief privacy officer and chief security officer, in partnership.

‍

But when we talk about AI governance, there are so many stakeholders. You have the CFO, who is interested in understanding the ROI, or sometimes lack thereof, from their AI investment. Of course, you have your board telling their C-suite leaders, make sure we're using AI, make sure we're embracing this, make sure everyone is using it in their day-to-day jobs. And that's also HR. Your CHRO is involved in helping drive that change organizationally.

‍

So there are a lot of stakeholders when it comes to AI governance. The leaders who best understand where the data is and how it's being processed are going to be that partnership between the chief privacy officer and the CISO, the chief information security officer. That partnership has always been critical, and now it's absolutely necessary to meet this moment.

‍

AI laws and regulations continue to develop. They change, and sometimes their application changes because of what's happening with government. Ultimately, as laws are enacted around AI that create real obligations for companies, it's going to be the chief data legal officer, in other words, who has to hold responsibility for that.

‍

When we think about AI governance today, it still needs to be very multi-stakeholder, simply because of what AI is able to impact across all functions. But the chief privacy officer, the chief data legal person at a company, does need to step into understanding where the data is that provides the inputs to an AI system.

‍

There are experts those lawyers will need to rely on to assess the fairness and safety of that system, and its processing integrity. But insofar as data is involved in AI, which it 100% is, and is hugely critical, the chief privacy officer is going to have to upskill and level up to meet that.

‍

Jad: Fantastic, Joyce. As you're helping those startups think through their AI governance programs, is your first recommendation to understand what data they're using, how data is flowing, and how it's going to AI? Or are you thinking more about a documentation exercise to build the right policies? What's the first thing you typically ask them to do?

‍

Joyce: Boy. I think it's so contingent on where the company is in its stage of development. The last thing I would ever want a fast-moving team to have to do is start filling out a bunch of audit materials and going through interrogatories about what they're doing and how they plan to do it.

‍

For one, it doesn't mesh with the rapid iteration that startups undertake, and should be doing, to develop their products and services. It's also not a great trust-building exercise to constantly be yanking the chain of a team that's out there trying to build something great.

‍

This might be a bit controversial, or maybe very innovative, but I'm also very interested in looking into AI observability platforms. What are the ways you can meet teams at the point of their agentic deployment? Are there more innovative things we can do, like plugging into the MCP alongside agents as they're being created and deployed? Are there ways to manage it on the back end and continue to observe it over time? When we think about governance and all the stakeholders involved, it would make for great business continuity to be able to harness the power of all the agentic workflows you've built or are continuing to build.

‍

Asking companies to slow down when they really should be speeding up is, at this point in history, not the best guidance. So instead, it's more about how you come in even earlier in that process. Of course, a lot of these things are very human-to-human. We have the relationships to trust each other. But from a tech perspective, can we come in even earlier? How do we get to a place where you have a single pane of glass to look at how data is flowing in and out of your company and being processed?

‍

I would love it if you have a recommendation, Jad, but I think most privacy and security leaders are waiting. We want that. There are certainly a lot of resources out there, but I don't yet know of a very strong solution that lets you see across all the contours of an organization's data processing.

‍

We could get quite technical, but suffice it to say: explore harnesses, explore setting up your own MCP, and make sure that matrixes really well with your ongoing security practices. There are so many ways you can think about how to come in earlier. In some ways, it's more technical than relational. As much as collaboration will continue to drive organizations and innovation, the speed at which companies and innovators are moving is going to be that fast. Gatekeeping or after-the-fact auditing is not going to be all that conducive, and probably not all that successful, for what you're trying to solve for.

‍

Jad: That's wonderful. Everything you said about coming in early, partnering well with teams so they're not slowed down in any way, and having that observability really resonates. The only thing I would possibly add is to make the argument for the company to also develop a strong privacy, data, or security team that can keep up, and do its own reviews, approaches, and defenses alongside the development of all these great features.

‍

Joyce, this has been an incredibly interesting conversation. Before we end the show, if listeners want to follow your work or get in touch with you, how do you recommend they do that?

‍

Joyce: Absolutely. For one, if you know Jad, you'll know me on LinkedIn, so you'll be able to find me there. Definitely send me an invite. Otherwise, my firm is called Chen & Foundry, at chenfoundry.com, so definitely take a look. But especially for your listeners, Jad, just send me an invite and follow me on LinkedIn. That'll be the best way to reach me.

‍

Jad: Joyce, thank you so much for your time. This was a lovely conversation. I really enjoyed it, and I look forward to following your next steps with your own privacy practice. Good luck.

‍

Joyce: Thank you so much. Looking forward to staying in touch, Jad.

‍